Section 2(u) · Section 8(6) · Rule 7
Rule 7: Personal Data Breach Intimation
When a personal data breach occurs, the DPDP Act and Rule 7 require Data Fiduciaries to intimate affected Data Principals and the Data Protection Board — with an initial Board intimation without delay and a detailed update within seventy-two hours (or a longer period the Board may allow).
What the Act and Rule 7 say
Section 2(u) defines a personal data breach as any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises the confidentiality, integrity or availability of personal data. Section 8(6) requires the Data Fiduciary, on becoming aware of a personal data breach, to take reasonable steps to intimate each affected Data Principal and the Board in such manner as may be prescribed.
Rule 7(1) requires intimation to each affected Data Principal without delay, in a concise, clear and plain manner, through the user account or any registered communication mode. That intimation must include a description of the breach (nature, extent and timing); likely consequences for the individual; measures implemented or being implemented to mitigate risk; safety measures the individual may take; and business contact information for queries.
Rule 7(2) requires intimation to the Board: first, without delay, a description including nature, extent, timing and location of occurrence and likely impact; and second, within seventy-two hours of becoming aware (or a longer period the Board allows on written request), updated and detailed information — including broad facts and reasons leading to the breach, mitigation measures, any findings regarding who caused the breach, remedial measures to prevent recurrence, and a report on intimations given to affected Data Principals.
What it means in practice
Build a breach response playbook that defines detection, escalation, legal/privacy ownership, and draft content for both Principal and Board intimations. The “without delay” and seventy-two-hour clocks start from becoming aware — so detection and decision logs matter. Coordinate with Rule 6 safeguards and logging so you can describe nature, extent, timing and remediation with evidence.
Identify affected Data Principals and communication channels early. Prepare templates that cover Rule 7(1) elements without over-promising facts still under investigation. For the Board package, plan how the initial short intimation and the seventy-two-hour detailed update will be assembled, approved and filed.
This page is informational. It does not invent Board portal workflows or claim that any ConsentifyAI product automates statutory breach intimation. Organisations should follow Board and MeitY guidance as published and obtain qualified advice for incident-specific decisions.
Common mistakes
- Waiting for a complete forensic report before any Board intimation when Rule 7 expects an initial description without delay and detail within seventy-two hours.
- Notifying only internal leadership while omitting affected Data Principals or the Board.
- Treating every security event as outside Section 2(u) without assessing confidentiality, integrity or availability impact on personal data.
- Lacking contact data or channels needed to reach affected Data Principals promptly.
Official source
ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.
Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.